Stored Cross-Site Scripting in Tournamatch Plugin for WordPress
CVE-2025-4594
6.4MEDIUM
What is CVE-2025-4594?
The Tournamatch plugin for WordPress is exposed to a significant security issue through its 'trn-ladder-registration-button' shortcode. This vulnerability arises from inadequate sanitization of user inputs and lack of proper output escaping, permitting authenticated users with contributor-level access or higher to inject malicious scripts. These scripts may run on user-accessed pages, thereby compromising site integrity and user security. Affected versions include all versions up to and including 4.6.1.
Affected Version(s)
Tournamatch * <= 4.6.1